QuestionQ57
Security EngineeringA nation-state actor is discovered attacking large corporations by establishing persistence in smaller companies that are likely to be acquired by those corporations. The actor then provisions user accounts in the companies for use after acquisition. Before an upcoming acquisition, a security officer performs threat modeling for this attack vector. Which of the following practices is the best way to investigate this threat?
- A Restricting internet traffic originating from countries in which the nation-state actor is known to operate
- B Comparing all existing credentials to personnel and services
- C Auditing vendors to mitigate supply chain risk during the acquisition
- D Placing a hold on all information about corporate interest in acquisitions
Community Discussion